Boss of the SOC (BOTS) Investigation Workshop for Splunk
Boss of the SOC (BOTS) Investigation Workshop for Splunk
This app is a companion app used for the Investigating with Splunk workshop and uses the BOTSv1 data that is hosted at Splunk.com. If you are interested in getting a guided tour of the BOTSv1 dataset, which includes both an APT and Ransomware scenario, this is the app to use!
Each scenario provides a guided walkthrough to better understand the scenarios and how an analyst can use Splunk to identify these kinds of techniques.